The ESL discount is real, and one database connection voids it
An Oracle Embedded Software License lets an ISV ship Oracle technology inside a packaged application at a restricted, application specific price, 70 to 90 percent below Full Use list: the ISV buys it, the end customer inherits it, and the Oracle component is usable only by the embedding application. The restriction is the whole point, and across our reviews the money was never in the original purchase. It was in what somebody plugged into the database afterward, almost always by accident.
Prepared by Redress Compliance · August 8, 2026 · Oracle advisory. Based on 15 to 25 restricted use license reviews run or benchmarked 2024 to 2025.
Executive summary
One connection voids the restriction, and 7 in 10 estates had made it.
The breaches are simple: no direct access, no ad hoc queries, no repurposing the database for a second application, and in about 7 of 10 embedded engagements a team had connected a reporting or integration tool directly to the embedded database.
The single act that converts restricted use into Full Use exposure.
Use creep beyond the licensed application appeared in 40 to 60 percent of the wider ESL and ASFU estate, and none of it was deliberate: a BI connector, an integration platform, a monitoring agent, each one wired in by someone solving a problem.
The breach reprices at 5 to 10 times, because the discount runs backward.
The ESL discount ran 70 to 90 percent below Full Use list at the original sale, and the true up after a breach cost 5 to 10 times the original ESL price, since Oracle can require conversion to Full Use at list for the whole deployment.
The economics are the audit's design: the deeper the original discount, the larger the catch up, which is why the embedded estate is worth auditing from Oracle's side and worth fencing from yours.
Half the customers could not produce the paper that defines their rights.
Both ends of the chain are auditable, Oracle can review the ISV and the customer running the embedded product, and roughly half of customers could not produce the embedding agreement, leaving them unable to define what they were entitled to do when the audit asked.
The defense is paper plus architecture: the embedding agreement on file with the named application identified, and documented isolation, who connects to the embedded database and with what tools, with every direct access path blocked.
A true up simply pays for the mistake; the paper and the fence prevent it.
The license type table is the map, and the ordering document is the territory.
ESL sits alongside ASFU, both restricted, different distribution models: the ESL is the ISV's license with the customer inheriting embedded rights, the ASFU is the customer's license via the ISV for one named application with full database access inside it.
And Full Use is the unrestricted price everything reprices toward. The license type and the named application are written into the ordering document, no ESL rate card exists on any price list, and the clause naming a single application is the line that defines the entire exposure.
The license types, compared
| License type | Who holds it | Use scope | The audit trap |
|---|---|---|---|
| ESL, embedded | The ISV buys, the customer inherits | Inside one application only | Direct database access |
| ASFU, application specific | The end customer, via the ISV | Full database, one named application | Use beyond the named application |
| Full Use | The end customer, direct | Any application, any workload | Unlicensed options and cores |
| OEM embedded | The ISV under agreement | Redistribution scope | Distribution beyond the grant |
The restriction is priced into the discount, and the discount defines the exposure.
The ESL is cheapest because its scope is narrowest, no direct access, no ad hoc SQL, no second application, and every relaxation of that scope belongs on ASFU or Full Use paper, priced before deployment rather than after an audit notice.
No ESL line exists on the Oracle Technology Global Price List and no part number can be looked up: the royalty schedule sits inside the ISV's own distribution agreement, which is why the embedding agreement is the customer's only statement of rights.
The fence, paper plus architecture
- Obtain and file the embedding agreement: the document half the customers could not produce, and the only definition of what you may do.
- Confirm the named application: the exact application in the ESL or ASFU ordering document, the line the whole exposure hangs on.
- Audit the connections: who connects to the embedded database and with what tools, because the breach is a connection, not a decision.
- Block the direct paths: every access route that bypasses the application interface, at the network and credential level, not the policy level.
- License the second use case before deployment: if the need is genuine, ASFU or Full Use paper priced calmly beats the 5 to 10 times true up priced under audit.
The Oracle CIO complete playbook
The restricted use boundaries inside the five year Oracle plan: the license types, the audit posture, and the conversion economics.
Get the white paper →How it breaks, and what the audit reads
The breach is almost never a decision: a reporting analyst points a BI tool at the database because the data is there, an integration platform gets credentials because the project needed a feed, a DBA runs ad hoc queries because that is what DBAs do.
And each act is invisible until an audit maps the connection log against the named application.
Oracle audits look for exactly this, use beyond the embedding application, and both ends of the chain are reviewable, the ISV's royalty compliance and the customer's use boundary.
The sibling model's mechanics, the ASFU's named application scope with full database access inside it, run in the ASFU license guide; the free base with paid component pattern that catches estates the same accidental way in the VirtualBox analysis.
And the audit sequence any finding lands in through the Oracle audit guide.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across restricted use reviews, 2024 to 2025
Fredrik Filipsson ran or benchmarked roughly 15 to 25 restricted use license reviews between 2024 and 2025, and the money was never in the original purchase:
Beyond the licensed application across the wider ESL and ASFU estate, almost always accidental.
The Full Use true up against the original ESL price, the discount running backward.
The defense splits cleanly into what wins and what pays: the embedding agreement plus documented isolation wins the argument, because the paper defines the rights and the architecture proves the boundary held, while a license true up simply pays for the mistake at the 5 to 10 times rate the original discount set up.
The half of customers who cannot produce their embedding agreement have conceded the definition of their own rights before the audit starts, which makes the filing cabinet, not the database, the first place a restricted use review looks.
Your first five moves
- Locate and file the embedding agreement today, the rights definition half of customers could not produce.
- Confirm the named application in the ordering document, the single line defining the exposure.
- Map every connection to the embedded database, since 7 in 10 estates had a tool wired in that voids the restriction.
- Block the direct access paths at credential level, because the breach is a connection, not a policy violation.
- Price any genuine second use case on the right paper before deployment, not at 5 to 10 times after. The Oracle practice runs the review with you.
Frequently asked questions
What is an Oracle ESL license?
An Embedded Software License: a restricted use license an ISV buys from Oracle and embeds inside its own product, with the end customer receiving the Oracle technology only as part of that application.
The discount runs 70 to 90 percent below Full Use list, the customer rarely sees a separate Oracle line item, and the Oracle component is not separately usable in any way.
What can you not do with an Oracle ESL?
Use the Oracle technology outside the embedding application, in any form: no connecting your own reporting or integration tools to the embedded database, no ad hoc SQL outside the application interface, and no serving a second application from the same database.
Each of those converts restricted use into Full Use exposure, and the first, a direct tool connection, appeared in 7 of 10 embedded engagements we reviewed.
What is the difference between ESL and ASFU?
Both are restricted use with different holders and scopes: the ESL belongs to the ISV with the customer inheriting embedded rights inside one application, while the ASFU is the end customer's license, bought via the ISV, granting full database access for one named application.
The ASFU costs more and flexes slightly further, and use beyond the named application is its trap, as direct access is the ESL's.
What happens if you breach ESL restrictions?
Oracle can require conversion to Full Use at list price for the deployment, and because the ESL was discounted 70 to 90 percent at sale, the true up ran 5 to 10 times the original ESL price in our reviews.
The deeper the original discount, the larger the catch up, which is the economics that make the embedded estate a reliable audit target.
Why does the embedding agreement matter?
It is the only document defining the end customer's rights, and roughly half of customers could not produce it, conceding the definition of their own position before any audit argument began.
The defense is paper plus architecture, the agreement on file with the named application confirmed, and documented isolation proving the use stayed inside the boundary; without the paper, the architecture defends nothing.
How do you audit your own ESL exposure?
Map the connections, not the installs: confirm the exact application named in the ordering document, inventory who connects to the embedded database and with what tools, block every path that bypasses the application interface at the credential level.
And file the embedding agreement where the audit response team can find it.
A genuine second use case gets licensed on ASFU or Full Use paper before deployment, at calm prices instead of the 5 to 10 times true up.